Red Hat released Important security updates for httpd:2.4 across multiple Red Hat Enterprise Linux 8 support channels to remediate two Apache HTTP Server vulnerabilities, CVE-2025-55753 and CVE-2025-58098. The first flaw affects mod_md ACME certificate renewal handling in Apache HTTP Server versions 2.4.30 through 2.4.65, where an integer overflow can drive the renewal backoff timer to zero after repeated failures and trigger continuous retry attempts until renewal succeeds. The second flaw affects Apache HTTP Server before 2.4.66 when Server Side Includes is enabled with mod_cgid, causing the shell-escaped query string to be passed to SSI #exec cmd="..." directives.
The fixes were shipped through advisories including RHSA-2026:0009, RHSA-2026:0010, RHSA-2026:0011, and RHSA-2026:0012, covering RHEL 8.2, 8.4, 8.6, and 8.8 service variants such as AUS, EUS, SAP, Telecommunications, and Advanced Mission Critical Update Support. Updated packages include httpd, mod_md, mod_http2, mod_ssl, mod_ldap, mod_proxy_html, and mod_session for supported architectures, while Apache identified version 2.4.66 as the upstream fix level for both issues.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-01-05, Red Hat issued RHSA-2026:0012, an Important httpd:2.4 security update for RHEL 8.8 Update Services for SAP Solutions, Telecommunications Update Service, and related variants. The update fixes CVE-2025-55753 and CVE-2025-58098 in Apache HTTP Server packages.
On 2026-01-05, Red Hat issued RHSA-2026:0011, an Important httpd:2.4 update for RHEL 8.6 Advanced Mission Critical Update Support, Update Services for SAP Solutions, and Telecommunications Update Service. The advisory addresses both CVE-2025-55753 and CVE-2025-58098.
On 2026-01-05, Red Hat issued RHSA-2026:0010, an Important httpd:2.4 advisory for RHEL 8.4 Advanced Mission Critical Update Support and 8.4 Extended Update Support Long-Life Add-On. The advisory delivers fixes for CVE-2025-55753 and CVE-2025-58098.
On 2026-01-05, Red Hat issued RHSA-2026:0009, an Important httpd:2.4 security advisory for Red Hat Enterprise Linux Server - AUS 8.2 x86_64. The update remediates CVE-2025-55753 and CVE-2025-58098 with updated Apache HTTP Server packages.
Apache HTTP Server fixed CVE-2025-55753, an integer overflow in mod_md ACME renewal backoff handling, and CVE-2025-58098, an SSI and mod_cgid issue that passes the shell-escaped query string to #exec cmd directives. Both Bugzilla records state the issues affect versions before 2.4.66 and recommend upgrading to 2.4.66.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.